post builds its body as params.merge('_csrf' => csrf) inside its own attempt block (lib/baza-rb.rb:744), and csrf is itself a get, which opens a second attempt loop (:546).
What happens: when /csrf is unreachable the inner loop burns @retries + 1 attempts and raises, then the outer loop re-runs the body construction and starts the inner loop again. retries: N costs (N + 1) squared requests.
retries:1 -> 4 GET /csrf attempts in 1.5s (BazaRb::TimedOut)
retries:2 -> 9 GET /csrf attempts in 5.4s (BazaRb::TimedOut)
retries:5 -> 36 GET /csrf attempts in 23.7s (BazaRb::TimedOut)
With the default retries: 5 one transfer fires 36 requests at /csrf and blocks for about 24 seconds. This is not a request to cache the token, which #361 already refused because the live server treats it as single use; the token still has to be fetched per attempt, only the nesting is wrong.
What should happen: the CSRF fetch should sit outside the POST's own retry region, so retries: N means at most N + 1 attempts in total.
postbuilds its body asparams.merge('_csrf' => csrf)inside its ownattemptblock (lib/baza-rb.rb:744), andcsrfis itself aget, which opens a secondattemptloop (:546).What happens: when
/csrfis unreachable the inner loop burns@retries + 1attempts and raises, then the outer loop re-runs the body construction and starts the inner loop again.retries: Ncosts(N + 1)squared requests.With the default
retries: 5onetransferfires 36 requests at/csrfand blocks for about 24 seconds. This is not a request to cache the token, which #361 already refused because the live server treats it as single use; the token still has to be fetched per attempt, only the nesting is wrong.What should happen: the CSRF fetch should sit outside the POST's own retry region, so
retries: Nmeans at mostN + 1attempts in total.